Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-10-22 | CVE-2017-15723 | NULL Pointer Dereference vulnerability in multiple products In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message. | 7.5 |
2017-10-22 | CVE-2017-15721 | NULL Pointer Dereference vulnerability in multiple products In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. | 7.5 |
2017-10-22 | CVE-2017-15228 | Out-of-bounds Read vulnerability in Irssi Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string. | 7.5 |
2017-10-22 | CVE-2017-15227 | Use After Free vulnerability in Irssi Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on. | 7.5 |
2017-10-22 | CVE-2017-15803 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.43 XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000150." | 7.8 |
2017-10-22 | CVE-2017-15802 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.43 XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResCompareResourceNames+0x0000000000000087." | 7.8 |
2017-10-22 | CVE-2017-15801 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xnview 2.43 XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77310000!LdrpResSearchResourceInsideDirectory+0x000000000000029e." | 7.8 |
2017-10-22 | CVE-2017-11292 | Type Confusion vulnerability in multiple products Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. | 8.8 |
2017-10-22 | CVE-2017-15735 | Cross-Site Request Forgery (CSRF) vulnerability in PHPmyfaq In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary. | 8.8 |
2017-10-22 | CVE-2017-15734 | Cross-Site Request Forgery (CSRF) vulnerability in PHPmyfaq In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php. | 8.8 |